|
219861
|
7.5 |
HIGH
Network
|
cockpit-project fedoraproject redhat
|
cockpit fedora virtualization
|
It was found that cockpit before version 184 used glib's base64 decode functionality incorrectly resulting in a denial of service attack. An unauthenticated attacker could send a specially crafted re…
|
CWE-909
Missing Initialization of Resource
|
CVE-2019-3804
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219862
|
4.1 |
MEDIUM
Local
|
mcafee
|
network_security_manager
|
Data Leakage Attacks vulnerability in the web portal component when in an MDR pair in McAfee Network Security Management (NSM) 9.1 < 9.1.7.75 (Update 4) and 9.2 < 9.2.7.31 Update2 allows administrato…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2019-3606
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219863
|
9.8 |
CRITICAL
Network
|
mcafee
|
network_security_manager
|
Authentication Bypass vulnerability in McAfee Network Security Manager (NSM) 9.1 < 9.1.7.75.2 and 9.2 < 9.2.7.31 (9.2 Update 2) allows unauthenticated users to gain administrator rights via incorrect…
|
NVD-CWE-noinfo
|
CVE-2019-3597
|
2024-11-21 13:42 |
2019-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219864
|
8.1 |
HIGH
Network
|
ovirt redhat
|
ovirt virtualization
|
It was discovered that in the ovirt's REST API before version 4.3.2.1, RemoveDiskCommand is triggered as an internal command, meaning the permission validation that should be performed against the ca…
|
CWE-862
Missing Authorization
|
CVE-2019-3879
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219865
|
6.5 |
MEDIUM
Adjacent
|
linux debian redhat canonical netapp
|
linux_kernel debian_linux enterprise_linux ubuntu_linux solidfire hci_management_node snapprotect active_iq_unified_manager_for_vmware_vsphere cn1610_firmware
|
The SCTP socket buffer used by a userspace application is not accounted by the cgroups subsystem. An attacker can use this flaw to cause a denial of service attack. Kernel 3.10.x and 4.18.x branches …
|
-
|
CVE-2019-3874
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219866
|
9.1 |
CRITICAL
Network
|
libssh2 debian netapp opensuse
|
libssh2 debian_linux ontap_select_deploy_administration_utility leap
|
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH packets with a padding length value greater than the packet length are parsed. A remote attacker who compromises a SSH…
|
CWE-125
Out-of-bounds Read
|
CVE-2019-3861
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219867
|
9.1 |
CRITICAL
Network
|
libssh2 debian netapp opensuse
|
libssh2 debian_linux ontap_select_deploy_administration_utility leap
|
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SFTP packets with empty payloads are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial …
|
CWE-125
Out-of-bounds Read
|
CVE-2019-3860
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219868
|
8.8 |
HIGH
Network
|
libssh2 debian netapp opensuse redhat fedoraproject oracle
|
libssh2 debian_linux ontap_select_deploy_administration_utility leap enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus …
|
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit signal are parsed. A remote attacker…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-3857
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219869
|
8.8 |
HIGH
Network
|
libssh2 debian netapp opensuse redhat fedoraproject oracle
|
libssh2 debian_linux ontap_select_deploy_administration_utility leap enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus …
|
An integer overflow flaw, which could lead to an out of bounds write, was discovered in libssh2 before 1.8.1 in the way keyboard prompt requests are parsed. A remote attacker who compromises a SSH se…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2019-3856
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219870
|
9.8 |
CRITICAL
Network
|
atlassian
|
confluence confluence_server
|
The WebDAV endpoint in Atlassian Confluence Server and Data Center before version 6.6.7 (the fixed version for 6.6.x), from version 6.7.0 before 6.8.5 (the fixed version for 6.8.x), and from version …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2019-3395
|
2024-11-21 13:42 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|